AMS Information Systems & Security Checklist
- Print
- Email
- | Updated: 6:15 pm ET September 10, 2008
Note:
- This is the complete checklist throughout your ISS Engineering activities during the AMS Lifecycle phases.
- The symbol "*" indicates that the FAA firewall access is required to view this link.
Initiate
FAA Information Systems Security (ISS) Activities Process:
- If any questions, please contact 9-ATOP-HQ-ISSE-Info@faa.gov, ATO-P Information Systems Security Chief Scientist Engineer.
- Go to the last page of this checklist to review:
- Appendix 1: "AMS Logo Map - FAA Lifecycle Management Process".
- Use the map to follow the numbered AMS decision points in the process with this checklist.
- Appendix 2: "Security Activities during AMS Phases"
- It is a quick overview of deliverable security related products for each AMS Phases.
- Use this checklist to map the security activities along with your appendix 1 & 2.
- Review the lettered content of the "FAA Information Systems Security (ISS) Engineering Process".
Resources
- The ATO ISS related websites:
- SCAP Templates and FAQs
Quick Links:
(Start: Service Analysis activities for the Mission Needs Decision (MND))
Note: The symbol "*" indicates that the FAA firewall access is required to view this link.
Review
- FAA FAST AMS Lifecycle Phases and Decisions guidance website:
Initiate
- Service Level Mission Need (SLMN) Threat Stipulation and basic security policy.
Deliverable(s):
- Statement of security policy and threat environment stipulation incorporated into the SLMN.
End SA for AMS decision point: #1
(Start: OMB Exhibit 300 Attachment 1 for the Investment Analysis Readiness Decision (IARD))
Note: The symbol "*" indicates that the FAA firewall access is required to view this link.
Review
Coordinate
- Service Unit/Service Area Certification Team Lead to determine plans and strategy for SCAP activities including determining the level of effort and security activities.
Generate
Deliverable(s):
- OMB Exhibit 300, Attachment 1: Preliminary Program Requirements (pPR)
- ISS Section of the Preliminary requirements. (pPR)
End CRD for AMS decision point: #2 & AMS Phase Mission Analysis (MA)
(Start: OMB Exhibit 300 Attachment 2 for the Initial Investment Decision (IID))
Note: The symbol "*" indicates that the FAA firewall access is required to view this link.
Review
Update
- CONOPS of system.
- ISS section of the Preliminary Requirements. (pPR document).
- Apply 800-53.
- Tailor 800-53 security requirements to your acquisitions.
Generate
- Basis of Estimates (BOE) on security cost estimates for alternatives.
- SCAP with your Service Unit/Service Area Certification Team Lead.
- The preliminary Information System Security Plan, (ISSP).
- Preliminary System Characterization/Categorization.
- Preliminary vulnerability and risk assessment.
Deliverable(s):
- BOE on security cost estimates for alternatives.
- OMB Exhibit 300, Attachment 2: Business Case Analysis Report (BCAR)
- Updated OMB Exhibit 300, Attachment 1: (pPR)
- Requirements for the ISS section of the (pPR) to include the 800-53 controls.
- Preliminary vulnerability and risk assessment.
- Preliminary SCAPs document
- Preliminary ISSP with security policy statement.
- Preliminary System Characterization/Categorization.
End IIA for AMS decision point: #3
(Start: OMB Exhibit 300 Attachment 3 for the Final Investment Decision (FID))
Note: The symbol "*" indicates that the FAA firewall access is required to view this link.
Review
Update
- SCAP with your Service Unit/Service Area Certification Team Lead.
- CONOPS of system.
- ISS section of the Preliminary Requirements for the Final Requirement Document (fPR).
- Security Interfaces document for inclusion in Interface Requirement Document (IRD).
- The ISSP.
- System characterization/categorization.(FIPS-199)
- Vulnerability and risk assessment.
Generate
- Initial Security Test Plan & Report.
- Note: Documentation should be produced only if test documents are being developed early based on approved system prototype, prior to Solution Implementation phase.
- Support for system addition to the ATO Five Year SCAP Plan with your Service Unit/Service Area Certification Team Lead and ISSO.
- Security Information for Solicitation Information Request (SIR), Contract Statement of Work (SOW) and Contract Data Requirement List (CDRL).
Obtain
- Stakeholders’ buy-ins and signing of the final security documents.
Deliverable(s):
- Updated OMB Exhibit 300, Attachment 1:
- (pPR) transformed into Final Requirement Document (fPR).
- OMB Exhibit 300, Attachment 2: Business Case Analysis Report (BCAR)
- OMB Exhibit 300, Attachment 3: Implementation Strategy/Planning (ISP)
- Final security vulnerability and risk assessment.
- SCAP documents
- ISSP with security policy statement.
- System characterization/categorization.
- Security Test Plan & Report (See note above.)
- Proposal of schedule, FIPS-199, and plan toward ATO Five Year SCAP Plan for your added system.
- The security information for SIR, SOW & CDRL.
- Stakeholders’ signatures on all finalized security documents
End FIA for AMS decision point: #4 & Phase: IA
(Re-baseline: OMB Exhibit 300, Attachment 1, 2 & 3 for the In-Service Decision (ISD))
Note: The symbol "*" indicates that the FAA firewall access is required to view this link.
Review
Update
- Security information for Solicitation Information Request (SIR), Contract Statement of Work (SOW) and Contract Data Requirement List (CDRL).
- Vulnerability and risk assessment for the Security Risk Assessment (SRA).
- CONOPS of system.
- ISS section for the Final Requirement Document (fPR).
- The ISSP.
- SCAP to reflect actual fielded systems with your Service Unit/Service Area Certification Team Lead and ISSO. Must complete the SCAP documents before operating the system.
Generate
- Security testing on system baseline and refine solution as needed for ISD/commissioning.
- Users guide, training plans, and contingency/disaster recovery plans.
Obtain
- DAA signature(s) of Certification and Authorization to connect and operate system in the NAS.
Deliverables:
- SCAP Implementation Guide (Reference: SCAP implementation guide - Section 4.1.1 *)
- Baselined OMB Exhibit 300, Attachment 1:
- ISS section of the Final Requirement Document (fPR).
- Security Interfaces in the IRD.
- Baselined OMB Exhibit 300, Attachment 2, & 3
- The security information for SIR, SOW & CDRL.
- DAA signature(s) of Certification and Authorization to connect and operate the system in the NAS.
End SI for AMS decision point: #5 & AMS Phase: SI
(Determine: To continue, update (Tech refresh, P3I) or end the Systems Development Lifecycle needs for the (ISM))
Note: The symbol "*" indicates that the FAA firewall access is required to view this link.
Review
Update
- ISS section of the Final Requirement Document (fPR).
- Vulnerability and risk assessment for the Security Risk Assessment (SRA).
- SCAP with your Service Unit/Service Area Certification Team Lead.
- Verify if recertification is required.
Generate
- Technology refresh and/or upgrade of the system assessed.
- For disposal of the system.
- Follow ISSP
- Archive information
- Sanitize media
- Dispose of hardware and software.
Obtain
- DAA signature(s) of Certification and Authorization package (SCAP).
Deliverables:
- Updated OMB Exhibit 300, Attachment 1, 2, & 3
- ISS section of the Final Requirement Document (fPR).
- Updated Security vulnerability and threat assessment for the SRA.
- Updated SCAP documents.
- DAA signature(s) of the SCAP documents.
End ISM for Systems Engineering Milestones: TRA & AMS Phase: ISM